## Thinking Path
`plugin-catalog/hindsight.yaml` already documented in prose that
`local_embedded` mode is unsupported on PM-managed Hermes with the current
pin — it still calls the retired lazy-install path for `hindsight-all` and
loops update takeover on every conversation — yet `hermes plugins install`
and the dashboard install path accepted the entry with no gate at all. Users
only discovered the trap after the death loop started. The catalog knew;
the installers didn't act on it.
## What Changed
- `hermes_cli/plugin_catalog.py`: new `known_issues: List[str]` field on
`PluginCatalogEntry` (parsed from `known_issues` in each `plugin-catalog/*.yaml`,
serialized into `to_dict()`, defaults to empty for backward compatibility).
- `plugin-catalog/hindsight.yaml`: declares the documented local-embedded trap
as machine-readable `known_issues`.
- `hermes_cli/plugins_cmd_install.py`:
- `cmd_install`: for catalog entries with `known_issues`, prints each issue
and a bold-red notice, then requires explicit confirmation. Non-interactive
(non-TTY) runs fail closed; interactive `y/N` runs require `y`.
- `dashboard_install_plugin`: non-interactive path refuses the entry outright
(no GUI bypass, mirroring the existing kill-list posture) and returns the
issue list in the error payload.
## Why This Shape
The trap is machine-readable in the catalog, so the enforcement lives in the
install entry points rather than in hindsight-specific code — any future
catalog entry that documents a known trap gets the same gate for free. The
non-interactive path fails closed because it cannot ask for the confirmation
the interactive path requires.
## Verification
- RED/GREEN double proof via git stash: pre-fix 7 failed / 3 passed, post-fix
10/10 passed (catalog parsing round-trip, hindsight.yaml declares the trap,
non-TTY refuse, TTY yes proceeds, TTY no cancels, custom-source install not
gated, dashboard refuse + unaffected path).
- Adjacent suites: test_plugin_catalog.py, test_plugin_validate.py,
test_plugins_hub_live_catalog.py all green (36 passed). 9 errors in
test_plugins_cmd_catalog.py reproduce identically with the fix stashed
(existing local `pm` / uv-sync environment limitation, unrelated).
- ruff clean on all changed files.
## Contract Change
New optional catalog field `known_issues` (list of strings). Entries without
it behave exactly as before. Install behavior changes only for entries that
declare `known_issues`.
## Risks
- Catalog entries that declare `known_issues` become gated installs. Authors
of future entries should only declare issues they want surfaced — this is
the intended trade (a documented trap must not install silently).
- `cmd_install` non-TTY automation installing hindsight by name now fails.
That is intentional: the trap cannot be confirmed non-interactively.
## Model Used
jd-deepseek-v4-flash-0731 (main session); pytest + ruff in the isolated
worktree.
## Related
#124037 (issue). Related: #122326 (resulting takeover loop), #7718
(`local_embedded` needs `hindsight-all`).
25 lines
1.3 KiB
YAML
25 lines
1.3 KiB
YAML
name: hindsight
|
|
repo: https://github.com/vectorize-io/hindsight
|
|
sha: 176f8c2de1369f569c489b831d143b78128b5535
|
|
subdir: hindsight-integrations/hermes
|
|
version: "1.0.1"
|
|
description: Hindsight long-term memory provider — knowledge graph, entity resolution and multi-strategy
|
|
retrieval (recall/reflect/retain tools plus automatic per-turn capture). Maintained by Vectorize;
|
|
cloud and local external modes are available. Local embedded mode is not supported on PM-managed
|
|
Hermes with this plugin pin — it still calls the retired lazy-install path for `hindsight-all`.
|
|
`hermes memory setup` fetches its bank-template catalog from raw.githubusercontent.com
|
|
(vectorize-io/hindsight main).
|
|
maintainer: vectorize-io
|
|
tier: community
|
|
category: memory
|
|
requires_hermes: ">=0.21.4"
|
|
known_issues:
|
|
- "Local embedded mode is not supported on PM-managed Hermes with this plugin pin — it still calls the retired lazy-install path for `hindsight-all`, which loops update takeover on every conversation. On managed installs prefer `local_external` or cloud mode."
|
|
docs_url: https://hindsight.vectorize.io/sdks/integrations/hermes
|
|
image: https://raw.githubusercontent.com/vectorize-io/hindsight/176f8c2de1369f569c489b831d143b78128b5535/hindsight-integrations/hermes/docs/banner.png
|
|
capabilities:
|
|
provides_tools: []
|
|
provides_hooks: []
|
|
provides_middleware: []
|
|
requires_env: []
|